Only the latest version of Vigil receives security updates. We do not backport fixes to older releases.
Vigil is open-source under the GNU Affero General Public License v3. If you discover a security vulnerability, please report it privately.
Do not open a public GitHub issue.
Instead, send a description of the vulnerability (including steps to reproduce, affected versions, and any potential impact) to:
- GitHub Issues (private) — Use the repository's "Report a vulnerability" feature under the Security tab, if enabled.
- Email — Reach out to the project maintainers directly at potentiallydangerous11@gmail.com
Reports will be acknowledged within 72 hours. You can expect an initial assessment within one week. We will keep you informed during the fix and disclosure process.
We appreciate responsible disclosure and will acknowledge contributors in release notes once a fix is published.
This policy covers the core Vigil codebase: @vigil/sdk,
@vigil/api, and apps/web. It does not cover third-party
dependencies or services you self-host alongside Vigil.